What is Risk Curator?
Risk Curator is a service for organisations that want to establish or improve their information security risk work in a structured and business-oriented way. The service helps you move from ad hoc assessments to a systematic risk programme that is understandable, manageable and actually used in decision-making.
Risk management is at the core of modern security standards and regulations — ISO 27001, ISO 27005, NIS2 and GDPR all require organisations to identify, assess and treat risks in a documented way. Risk Curator gives you the methodology, tools and support to build up this work in a way that is proportionate and sustainable.
What Risk Curator can include
- Design of methodology and process for information security risk management
- Conducting risk identification and risk analysis with relevant stakeholders
- Establishment and maintenance of a risk register with consistent classification and ownership
- Support in risk treatment — selection of controls, acceptance decisions and action plans
- Risk assessment for specific processes, systems or initiatives (e.g. DPIA for GDPR)
- Governance and reporting of risks to management and board
The result is a living risk programme that creates a shared language around risk in the organisation and gives management the decision-making basis they need to prioritise the right efforts.
When does Risk Curator fit?
Risk Curator suits organisations that lack a formal framework for risk management, or whose existing risk work is fragmented and difficult to aggregate and report. It also suits organisations preparing for an ISO 27001 certification, where the risk management process is one of the central requirements.
The service is also relevant for organisations that need to carry out Data Protection Impact Assessments (DPIA) under GDPR, or that want to ensure their risk assessments meet the requirements in NIS2 and DORA. We help you make risk work concrete and meaningful — not just a compliance exercise.
How we work with Risk Curator
We start by understanding your business, your assets and your threat landscape — and from that we tailor a risk management methodology that is relevant and proportionate for your situation. This may involve building an entirely new framework, or structuring and strengthening an existing one.
We work closely with your key people to identify and assess risks in a way that reflects reality, and help you translate risk assessments into concrete treatment decisions with clear ownership. The risk register is kept alive and actively used as a governance tool — not as a document gathering dust.